Re: Massive failed FTP attempts.



I use a log-monitoring perl script (similar to what many have done for ssh) which locks out offending hosts via iptables. If you're interested, I'll email it to you.

Robert


Michael Nielson wrote:
I run several small LAMP virtual servers, I've noticed a large amount of failed FTP login attempts, these all attempt to login with common FTP usernames like Administrator, or webmaster (the FTP server is proFTPd version 1.2.10). The attacker will try from one IP address maybe 30 or 40 times and then moving to a new IP address. I have several questions, first what are they trying to do? Crack my password? Or exploit a bug with proftpd? I've been more diligent about choosing a difficult to break password. More important what can I do to limit the number of attempts on my server? Thanks tons!
Michael




Relevant Pages

  • RE: [fw-wiz] OT: FTP Servers
    ... I'd suggest proftpd. ... I found that one pretty stable and it has good security vulnerabilities ... > I have been tasked to build a FTP server. ... > time I built a Unix FTP server I ...
    (Firewall-Wizards)
  • Re: ftp security tips?
    ... > I have no idea what FTP server I'm using. ... > 530 Please login with USER and PASS. ... That doesn't look like proftpd. ...
    (comp.os.linux.misc)
  • Looking for a secure ftp sw
    ... At present we are using ProFTPD on our ftp server. ... sftp instead of ftp access to these project accounts. ... Is there a better FTP SWthan ProFTPD for server usage? ...
    (RedHat)
  • [SUMMARY] Secure FTP server recommendations
    ... After some investigating I decided to use mod_tls with ProFTPd. ... if fail exit 1 Connection failed ... if fail exit 1 ftp dir: ... Any recommendations for a secure FTP server product for Solaris? ...
    (SunManagers)
  • Re: Microsoft FTP Server problem on W2K?
    ... It is a UNISYS ClearPath mainframe system that is trying to FTP using ... passive mode to a MS FTP server. ... Currently the mainframe FTPs in ACTIVE mode. ... Since the mainframe pushes files to our customers over a WAN connection, ...
    (microsoft.public.inetserver.iis.security)

Loading